Version 3.6.2
June 5, 2026
Release Type
Stable – Incremental Feature Release
Summary
Version 3.6.2 lands a new Accessories module that finally tracks the chargers, cases, styluses, and cables that ship out alongside your devices — issued individually or bundled with a checkout, with replacement-threshold warnings when the same charger gets handed to the same student one too many times.
A second major area of investment is sign-in. Microsoft 365 (Entra ID) joins Google as a zero-configuration sign-in option, ClassLink LaunchPad is now wired through a central-proxy multi-tenant flow that just works for every district, and the Admin SSO Settings page has been redesigned around brand-coloured identity provider rows with a Force-SSO master toggle.
The User Portal has grown: students and staff get a My Checkouts page with current devices and full handoff history, a Pre-Issuance Review readout that surfaces missing fields and recent logins on the admin user profile, and a refreshed ticket-entry picker that handles cart slots, cart-level tickets, permanently attached devices, and rooms a teacher is responsible for.
Plus a configurable Pre-Issuance Review with audience-scoped checks, OneRoster custom-field metadata mapping that lets SIS-side metadata values (bus route, graduation year, cohort, etc.) flow straight onto a Manage1to1 user custom field, a mergefield catalog for Smart Rules notifications, a hardened CSV export pipeline that no longer paints an HTML error page over your file, and customizable password generation.
Marquee features:
- Accessories Module — catalog, inventory, per-user issuance, bundle-with-checkout, replacement-threshold warnings
- Microsoft 365 SSO + ClassLink Multi-Tenant + SSO Settings Redesign — zero-config sign-in for the three big providers
- Pre-Issuance Review — at-a-glance user-readiness panel with configurable checks
- OneRoster Custom-Field Metadata Mapping — bind a Manage1to1 custom field to a SIS metadata key and let nightly syncs keep it current
- User Portal Expansion — My Checkouts, cart-slot ticket picker, room-responsibility devices, expanded docs
- Lost Device Flow Polish — keep-on-profile option, lost-accessory tracking, handoff jump for bundled accessories
- Smart Rules Mergefield Catalog —
{$incident_id}/{$fullname}/{$school}and 25+ other tokens for notify-admin email subject + body - Customizable Password Generation — district-controlled rules for generated passwords
Plus a CSV-export hardening pass, password-manager autocomplete suppression site-wide in /admin, an improved import pipeline that tolerates duplicate columns and classic-Mac line endings, and a round of bug fixes including a critical fix for the Device-Full export 500 and the Dashboard Recent Devices widget.
New Features
Accessories Module
The new Accessories module gives chargers, styluses, hard cases, screen protectors, USB-C cables, and headphones their own dedicated home — separate from Parts Inventory (which is for internal repair components). You define your district's accessory catalog, track stock at each location, and issue accessories to users — either on their own or bundled with a device checkout.
Catalog & Inventory
- A district-wide catalog of accessory types (Charger, Stylus, Hard Case, etc.) — each with a name, SKU, default cost, description, and an active / deactivated flag
- Per-location on-hand counts that share the same inventory locations as Parts (one location per warehouse / tech office)
- Adjust Stock for received shipments or damaged-on-arrival write-offs, Transfer between locations with a reason, and a full recent-transfers history per accessory
Per-User Issuance
- An Accessories card on every user profile lives between Current Checkouts and Current Incidents
- Issue an accessory inline: pick from the catalog dropdown, choose the source location, set status to Accepted or Declined (refusals still record for audit but don't decrement stock)
- Optional "Don't decrement stock for this issuance" checkbox for paper-trail-only entries
- Every accepted row has an inline Mark Lost action that flips status without auto-issuing a replacement; can be reversed with Mark Found if it turns up
Bundle With a Checkout
- When a device gets checked out, the Bundle Accessories modal opens automatically against the new lease
- Scan a barcode (or type a SKU) to auto-tick the matching accessory row, or click checkboxes manually
- Per-row "From Location" so a charger from Central Warehouse and a case from the tech office can ride one bundle
- Bundled accessories show up grouped under the device's asset tag on the user profile, and listed on the device profile's new Accessories on This Device card
Check-In Handoff
- After a standard check-in, a yellow banner appears on the user profile if accessories from that lease are still active
- Process Handoff opens a page with the active accessories and three decision buttons per row: Returned (closes assignment, restocks the source location), Keep (user keeps it, row stays open but un-nests from the device), Lost (stamps loss timestamp, no stock change)
- Mixed decisions are normal — return the case, keep the stylus, mark the charger lost in one save
Replacement-Threshold Warning
- When a user has been issued the same accessory 3 times in the trailing 12 months (bundled or standalone, lost or not), a yellow banner appears on their Accessories card
- The threshold is per-district configurable via the
AccessoryReplacementWarningThresholdsetting in Settings → Configure General Settings — set higher to relax, set to0to disable entirely
Documentation: Accessories Overview · Bundling Accessories With a Checkout · Issuing, Losing, and Replacing an Accessory
Sign-In Overhaul
3.6.2 overhauls the Single Sign-On experience on three fronts at once.
Microsoft 365 (Entra ID) SSO — A new Sign in with Microsoft option appears on the admin login page and User Portal sign-in page out of the box. Works with any Microsoft 365 / Entra ID tenant — typical for districts running Microsoft school environments. Same zero-config story as Google: no app registration on the district side, no API keys to paste, no admin consent setup required for individual users. Personal Microsoft accounts (@outlook.com, @hotmail.com, Xbox / Skype) are correctly rejected — only work and school accounts issued by an Entra tenant are accepted.
ClassLink Multi-Tenant Rewrite — ClassLink SSO is now wired through a Manage1to1-hosted central proxy so every district works with no per-district ClassLink app to register, no client IDs to copy, and no domain-allowlist round-trips. Users click Sign in with ClassLink, authenticate against their district's LaunchPad, and land back at Manage1to1 already signed in.
Admin SSO Settings Redesign — The Settings → SSO Settings page has been rebuilt around a clean per-provider row layout with brand-coloured identity-provider chips (Google blue, Microsoft cyan, ClassLink navy) and No Configuration Required badges so you can see at a glance which providers are zero-setup. A new Force Single Sign-On master toggle at the top of the page hides the password sign-in form entirely once you've verified at least one provider works end-to-end for your admins — useful for districts standardising on centralised identity.
Documentation: SSO Settings · Enabling Single Sign-On for Your District
Pre-Issuance Review
A new Pre-Issuance Review panel sits in the left column of every user profile — designed for techs who want to confirm a student or staff member is set up correctly before issuing hardware, without hunting through tabs.
The panel shows two things at a glance:
- Profile — a Complete / Incomplete indicator driven by checks your district has enabled. Hover to see exactly which check is failing.
- Recent Logins — the five most recent times this user signed in to the User Portal, with date / time, sign-in method (Password, Google SSO, Microsoft 365 SSO, ClassLink SSO, or Magic Link), and source IP. Useful when a user says "I can't log in" — quickly tells you whether they ever have.
Configurable checks — the new Settings → Pre-Issuance Review page lets you choose which user-profile fields count toward Complete: Email address, Username, Building assigned, Grade assigned (students only), Guardian email (students only), Guardian phone (students only). Audience-scoped checks automatically skip the opposite role, so a staff record won't show Incomplete just because there's no guardian email on file.
The default check set (Email + Username + Building) is the historic baseline; districts that need parent-comm coverage typically also enable Guardian email.
Documentation: User Profile — Pre-Issuance Review Panel · Pre-Issuance Review Settings
OneRoster Custom-Field Metadata Mapping
User custom fields can now be bound to a OneRoster metadata key so SIS-driven values flow into Manage1to1 automatically.
OneRoster lets your SIS attach district-specific metadata values to each user — typical examples are bus route, graduation year, cohort, and program track. When you create a user custom field, the new OneRoster Metadata Key input binds the field to one of those keys. Every subsequent OneRoster sync writes the SIS value onto every matching student's profile — no manual entry needed.
- Bound fields are SIS-owned — the OneRoster sync overwrites any manual edits on the next tick, so leave the Metadata Key blank if you want a manually-maintained field
- The key must start with a letter and contain only letters, digits, and underscores
- Unbound fields keep working as before — this is opt-in per field, not a global switch
Documentation: Custom Fields Tab — OneRoster Metadata Key · Mapping SIS Data into User Custom Fields
User Portal Expansion
The User Portal grew substantially in 3.6.2.
My Checkouts — A new dedicated page on the student / staff portal shows the user's current devices (with serial, asset tag, building, condition notes, and checkout date) and their full handoff history (every device they've ever had, when they got it, when they returned it). Gives students and parents a clear self-service view without contacting IT.
Cart-Slot Ticket Picker — When a student opens the ticket-entry form and they're on a cart-based lease, the picker drills into the cart so they can specify which slot / which device they're reporting an issue with — instead of just "the cart". The submitted ticket carries the specific slot + serial so the tech doesn't have to guess.
Cart-Itself Option — For tickets about the cart's hub, lid, missing keys, etc. (rather than a specific Chromebook on the cart), the picker now offers a "The cart itself" option that records the ticket against the cart_lease rather than any individual device.
Permanently Attached Devices — Devices that are fixtures inside a cart (charging hubs, locks, sensors) now appear in the ticket picker for the teacher who has the cart checked out, even though those devices don't have leases of their own.
Rooms You Manage — If a teacher is responsible for a room, the devices in that room (ViewSonic boards, cameras, etc.) appear in the picker too, even without an individual lease.
Submitter IP on Tickets — Tickets and end-user replies submitted via the User Portal now display the submitter's IP address on the admin-side ticket profile, useful for triage and security investigations.
Expanded Documentation — The User Portal docs section now covers Signing In, Dashboard, My Tickets, My Checkouts, Knowledge Base / Help Center, Your Profile, and Parent Portal (including AUP signing) as dedicated pages.
Documentation: User Portal · Submitting Tickets From the User Portal
Lost Device Flow Polish
Marking a device lost is now more nuanced:
- Keep on profile — by default, marking a device lost keeps the lease open so the device stays visible on the user's profile. Tick Also end this checkout in the mark-lost modal if you want to close the lease at the same time (the legacy behaviour).
- Lost-accessory tracking — a free-text notes field on the mark-lost flow captures what accessories went missing along with the device (e.g. "charger, stylus"), surfaced on the user profile next to the Lost badge.
- Handoff jump for bundled accessories — if the lost device's lease has active bundled accessories, marking the device lost takes you straight to the Accessory Handoff page so you can decide per-accessory whether each is Returned, Kept by the user, or also Lost.
Documentation: Marking Devices Lost
Smart Rules Mergefield Catalog
Smart Rules Notify admin(s) by email actions now support a documented catalog of merge fields you can drop into the subject and body of the notification.
- Incident-target rules get 17 tokens:
{$incident_id},{$incident_date},{$incident_status},{$incident_completed_date},{$incident_assessment},{$incident_repair},{$incident_url},{$fullname},{$first_name},{$last_name},{$email},{$grade},{$school},{$building},{$device_serial},{$device_barcode},{$device_model} - Device-target rules get 11 tokens:
{$device_id},{$device_serial},{$device_barcode},{$device_model},{$device_status},{$device_url},{$building},{$assigned_to_fullname},{$assigned_to_first_name},{$assigned_to_last_name},{$assigned_to_email} - An Available merge fields collapsible block appears under the body textarea on the rule edit page, listing every token with what it expands to — no guessing
- Unknown tokens stay literal in the rendered email so typos are visible instead of silently dropped
Documentation: Smart Rules — Merge fields in the notification subject and body
Customizable Password Generation
Districts can now control the rules used when Manage1to1 generates a password — for new user creation, password resets, and the admin password generator on the user profile.
- Configure password length, character classes (uppercase, lowercase, digits, symbols), and complexity requirements
- The same rules drive every password the system generates, so generated passwords always meet district policy
Documentation: Password Generation Rules
Configurable Pre-Issuance Review Checks
(See Pre-Issuance Review above — the configuration UI ships in 3.6.2 alongside the panel itself.)
Accessory-Lost Flag on Lost-Device Flow
(See Lost Device Flow Polish above.)
Warehouse Receive Transfer — Signature Capture
Receiving a warehouse-to-campus transfer now captures a digital signature at the campus end, completing the audit trail that the warehouse-side signature started.
Parts Check-Out — Transfer to New Location
The parts check-out flow can now transfer a part to a different location at check-out time, with quantity and reason captured. Useful for tech-to-tech part hand-offs that previously required two separate transfer steps.
Improvements
Accessories Polish Pass
Layout, spacing, and theme handling across the Accessories module got a comprehensive cleanup. The user-profile accessory card now reads cleanly in both light and dark themes, and stock-count badges use theme-neutral styling so they stay legible regardless of theme.
Accessories Scan-to-Issue + Standardized Picker Styling
The Issue Accessory modal now accepts a scanned barcode or typed SKU to auto-select the catalog entry. The Select-style dropdowns used across admin forms have been standardised so every picker looks and behaves the same.
Admin Password-Manager Autocomplete Suppression
Browser password managers (LastPass, 1Password, Bitwarden, native browser autofill) are now suppressed across the admin area — except on the login page (where they're expected) and My Profile (where staff change their own password). Stops the common "browser autofilled my district email into the wrong field" failure mode when an admin is editing another user's record.
Apple School Manager AppleCare — Rate-Limit Throttling + Quieter Activity Log
AppleCare coverage lookups against Apple School Manager are now throttled to stay within Apple's published rate limits — important for larger districts whose sync volume previously tripped throttling mid-run. The debug stream those lookups produce has also been moved out of the user-visible Activity Log so it no longer crowds out real activity entries.
Bug Fixes
-
MAN-1164 — Resolved an issue where the Device Full export could fail to complete and produce an unusable file. Both the manual and scheduled exports now run to completion reliably.
-
MAN-1124 — Resolved an issue where the Recent Devices dashboard widget could fail to render. The widget now loads reliably.
-
MAN-1131 — Imports that contained duplicate column names in the header row previously appeared to succeed without writing any rows. The importer now surfaces the duplicate-column condition clearly and aborts the import so the file can be corrected and re-uploaded.
-
MAN-1132 — Student / Staff imports saved on older Mac systems were treated as a single row, and any unknown header columns were silently ignored. Both behaviours are fixed: line endings are normalised before parsing, and unknown columns now surface as a warning so they aren't missed.
-
MAN-1134 — Incident profiles could occasionally surface the wrong insurance policy for devices that had been covered by multiple policies over time. The policy shown is now the one active on the incident date.
-
MAN-1176 — If an export ran into an error part-way through, the error page itself could end up inside the downloaded file. Exports that hit an error now produce a clean truncated file with a short error indicator instead.
-
MAN-1175 — Tokens like
{$incident_id}and{$fullname}in the Smart Rules Notify admin(s) by email subject and body previously rendered as literal text. They now resolve correctly — see Smart Rules Mergefield Catalog for the full list. -
MAN-1174 — Resolved an issue where the Lost Device Report could return an error. The report now loads reliably.
-
MAN-1159 — Resolved an issue where the Parts Transfers and Parts Adjustments tables could fail to load. Both tables now populate reliably.
-
MAN-1163 — Resolved an intermittent error in the Sign in with Google callback. The round-trip now completes reliably.
-
MAN-1165 — Editing a device and changing only custom-field values previously didn't persist. Custom field changes are now saved correctly whether or not core device fields changed.
-
MAN-1129 — Districts on a non-UTC time zone could appear stale on the Cron Status page even when cron was running normally. Time zone handling is fixed.
-
MAN-1138 — The Scheduled Reports cron previously wrote activity-log rows on every tick whether or not it had work to do. It now only logs when work runs.
-
MAN-1156 — Activity-log rows recorded during a system update could be attributed to the user who happened to trigger the update. They are now attributed to System consistently.
-
MAN-1118 — A district saw clearly impossible Google MDM sync counts and storage figures. Aggregation is fixed.
-
MAN-1119 — The Campus Summary widget could show wrong totals for buildings that had been renamed mid-year. Totals are now correct after a rename.
-
MAN-1123 — Resolved a favicon load failure on the admin and client-area pages.
Notes for This Release
- No breaking API changes — every external API endpoint behaves identically.
- Rolling out Force SSO? If you're switching your district to SSO-only sign-in with this release, see the Enabling Single Sign-On guide for the recommended verification + communication sequence before flipping the master toggle.
Changelog
| Type | Issue | Description |
|---|---|---|
| NEW FEATURE | MAN-1143 | Accessories module: catalog, inventory, per-user issuance, replacement-threshold warning |
| NEW FEATURE | MAN-1173 | Bundle accessories with a device checkout + check-in handoff page |
| NEW FEATURE | MAN-1170 | Accessory scan-to-issue + standardized Select2 picker helper |
| NEW FEATURE | MAN-1166 | Microsoft 365 (Entra ID) Single Sign-On — zero configuration |
| NEW FEATURE | MAN-1167 | ClassLink Single Sign-On — central-proxy multi-tenant rewrite |
| NEW FEATURE | MAN-1142 | Pre-Issuance Review panel on user profile (Profile + Recent Logins) |
| NEW FEATURE | MAN-1171 | OneRoster metadata key binding on user custom fields |
| NEW FEATURE | MAN-1153 | User Portal — My Checkouts page (current devices + handoff history) |
| NEW FEATURE | MAN-1148 | User Portal ticket entry — cart-slot picker + "the cart itself" option |
| NEW FEATURE | MAN-1155 | User Portal ticket entry — permanently attached devices + Rooms You Manage |
| NEW FEATURE | MAN-1154 | Submitter IP on tickets and end-user replies (admin-side) |
| NEW FEATURE | MAN-1145 | Lost Device flow — keep on profile, accessories-lost tracking |
| NEW FEATURE | MAN-1151 | Lost Device flow — jump to Accessory Handoff page |
| NEW FEATURE | MAN-1141 | E-signature capture on warehouse-to-campus transfer receipt |
| NEW FEATURE | MAN-1147 | Parts check-out — transfer to a new location with quantity + reason |
| NEW FEATURE | MAN-457 | Customizable password generation rules |
| NEW FEATURE | MAN-1160 | Warehouse receive-transfer signature capture |
| IMPROVEMENT | MAN-1172 | Per-district configurable Pre-Issuance Review checks |
| IMPROVEMENT | MAN-1168 | Admin SSO Settings page redesign + brand-color identity buttons |
| IMPROVEMENT | MAN-1169 | Accessories module visual polish pass |
| IMPROVEMENT | MAN-1122 | Suppress password-manager autocomplete site-wide in /admin |
| IMPROVEMENT | MAN-1125 | Throttle AppleCare coverage lookups within Apple School Manager rate limits |
| IMPROVEMENT | MAN-1130 | Move ASM AppleCare debug logging out of the Activity Log |
| IMPROVEMENT | MAN-1135 | Suppress upstream advisory noise on dependencies we've audited |
| IMPROVEMENT | MAN-1139 | Enrich cron run-log error payload for faster operator triage |
| BUG FIX | MAN-1164 | Device-full export failing on download |
| BUG FIX | MAN-1124 | Dashboard Recent Devices widget could fail to load |
| BUG FIX | MAN-1131 | Student import silent failure on duplicate column names |
| BUG FIX | MAN-1132 | Student/Staff import on older Mac line endings |
| BUG FIX | MAN-1134 | Wrong device insurance shown on incident profile |
| BUG FIX | MAN-1176 | Export error page captured into downloaded file |
| BUG FIX | MAN-1175 | Smart Rules notification merge fields rendered as literal text |
| BUG FIX | MAN-1174 | Lost Device Report error on load |
| BUG FIX | MAN-1159 | Parts Transfers and Adjustments tables not loading |
| BUG FIX | MAN-1163 | Sign in with Google occasional callback error |
| BUG FIX | MAN-1165 | Device edit custom-field-only changes not saving |
| BUG FIX | MAN-1129 | Cron Status page Central-time-zone tenants flagged stale |
| BUG FIX | MAN-1138 | Scheduled Reports extra activity-log rows on idle ticks |
| BUG FIX | MAN-1156 | System updates wrong attribution in Activity Log |
| BUG FIX | MAN-1118 | Google MDM sync statistics clearly wrong |
| BUG FIX | MAN-1119 | Campus Summary widget incorrect totals after building rename |
| BUG FIX | MAN-1123 | Favicon 404 on admin and client-area pages |
| BUG FIX | MAN-1162 | Lost-Device demo seed referenced an unknown column |
| TASK | MAN-1150 | Demo seed-data realism pass (internal) |
| TASK | MAN-1152 | Consolidate client-area SSO providers behind ClassLink rewrite |
| TASK | MAN-1149 | Expand User Portal documentation |
| TASK | MAN-1177 | StatusPage.io embed on admin login + admin chrome |